curl / Docs / Vulnerability table / 7.27.0 vulnerabilities

Vulnerabilities in curl 7.27.0

curl version 7.27.0 was released on July 27 2012. The following 78 security problems are known to exist in this version.

FlawFrom versionTo and including
cookie injection with none file7.
more POST-after-PUT confusion7.78.0.1
IDN wildcard match7.
siglongjmp race condition7.
SSH connection too eager reuse still7.
GSS delegation too eager connection re-use7.
FTP too eager connection reuse7.
SFTP path ~ resolving discrepancy7.
TELNET option IAC injection7.77.88.1
HTTP Proxy deny use after free7.
POST following PUT confusion7.77.85.0
control code in cookie denial of service4.97.84.0
FTP-KRB bad message verification7.
TLS and SSH connection too eager reuse7.
Auth/cookie leak on redirect4.97.82.0
Credential leak on redirect4.97.82.0
STARTTLS protocol injection via MITM7.
Protocol downgrade required TLS bypassed7.
TELNET stack contents disclosure again7.77.77.0
Bad connection reuse due to flawed path name checks7.
Metalink download sends credentials7.
Wrong content via Metalink not discarded7.
TELNET stack contents disclosure7.77.76.1
Automatic referer leaks credentials7.
FTP wildcard stack overflow7.
trusting FTP PASV responses4.07.73.0
curl overwrite local file with -J7.
TFTP small blocksize heap buffer overflow7.
TFTP receive buffer overflow7.
warning message out-of-buffer read7.
NTLM password overflow via integer overflow7.
RTSP bad headers buffer over-read7.
RTSP RTP buffer over-read7.
LDAP NULL pointer dereference7.
FTP path trickery leads to NIL byte out of bounds write7.
HTTP authentication leak in redirects6.07.57.0
FTP wildcard out of bounds read7.
IMAP FETCH response out of bounds read7.
FTP PWD response parser out of bounds read7.77.55.1
TFTP sends more than buffer size7.
--write-out out of buffer read6.57.53.1
printf floating point buffer overflow5.47.51.0
Win CE Schannel cert wildcard matches too much7.
Win CE Schannel cert name out of buffer read7.
cookie injection for other servers4.97.50.3
case insensitive password comparison7.77.50.3
OOB write via unchecked multiplication7.
double free in curl_maprintf5.47.50.3
double free in krb5 code7.37.50.3
curl_getdate read out of bounds7.
URL unescape heap overflow via integer truncation7.
Use after free via shared cookies7.
invalid URL parsing with '#'
IDNA 2003 makes curl use wrong host7.
curl escape and unescape integer overflows7.
Incorrect reuse of client certificates7.
TLS session resumption client cert bypass5.07.50.0
Re-using connections with wrong client cert7.77.50.0
Windows DLL hijacking7.
TLS certificate check bypass with mbedTLS/PolarSSL7.
remote filename path traversal in curl tool for Windows4.07.46.0
NTLM credentials not-checked for proxy connection re-use7.
sensitive HTTP server headers also sent to proxies4.07.42.0
Negotiate not treated as connection-oriented7.
Re-using authenticated connection when unauthenticated7.
URL request injection6.07.39.0
duphandle read out of bounds7.
cookie leak with IP address as domain4.07.37.1
not verifying certs for TLS to IP address / Schannel7.
not verifying certs for TLS to IP address / Secure Transport7.
IP address wildcard certificate validation7.
wrong re-use of connections7.
re-use of wrong HTTP NTLM connection7.
cert name check ignore with GnuTLS7.
cert name check ignore OpenSSL7.
URL decode buffer boundary flaw7.77.30.0
cookie domain tailmatch4.77.29.0
SASL buffer overflow7.

CVE data for 7.27.0 provided as JSON.

Changelog for curl 7.27.0

See vulnerability summary for the previous release: 7.26.0 or the subsequent release: 7.28.0